Skip to content

Comment on You don’t need SMS-2FAparent

Comments

SMS should only ever be used as a proof of investment. IE making sure a bit setting up hundreds of thousands of accounts (because they broke your CAPCHA) needs to buy tens of thousands of real phone numbers with service.

It’s a one time thing at account creation and should be immediately deleted afterwards.

Real 2FA should be set up afterwards to actually protect the account. A yubikey or even a simple TOTP app is a lot of protection against account takeover. The only big weakness left at that point is the help desk.

TOTP app

This is only very marginally more effective than SMS. Phishing is way more common and can be automated much more easily than SIM-swapping. With TOTP you close a small window but leave the big door open.

Yubikeys prevent phishing, which is enormously valuable.

All the arguments in the post against SMS 2FA are also arguments against TOTP

There is no help desk that can give away your TOTP secret. That’s the big weakness with SMS, someone buys a phone and asks the clerk to give them your phone number.

It is a publicized weakness. In practice, phishing is scalable and social engineering isn’t. And humans are shit at detecting phishing attacks.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.